Skip to main content

Ahsay Go - Microsoft 365 Requirements

September 16, 2026

Public Folder Backup

A licensed Exchange Administrator or a licensed user with Public Folder permission is required, otherwise you will not be able to access the public folder to select items and for backup or restore.

Starting October 1, 2026, Microsoft will start disabling the Exchange Web Services (EWS) and will be fully shutdown on April 1, 2027. This will affect public folder backup which will no longer be supported for backup since Microsoft Graph and other modern APIs do not fully support Public Folders.

Java Heap Size

The default Java heap size setting is 2048MB which is sufficient for Microsoft 365 backups based on the default four (4) concurrent backup threads.

The Java heap size should only be increased if the number of current backup threads is increased as more backup threads is expected to consume more memory. But this does not guarantee that the overall backup speed will be faster since there will be an increased chance of throttling.

As the value of four (4) concurrent backup threads is found to be the optimal setting for Microsoft 365 backups, to ensure best backup performance, minimal resource usage, and lowest probability of throttling of Ahsay backup requests by Microsoft 365.

For more detailed information on how to increase the backup thread, please refer to the How to Increase the Number of Concurrent Backup Threads.


Microsoft 365 License Requirement

  • Microsoft 365 Subscription Plan

    The following subscription plans with Microsoft 365 email services are supported to run backup and restore on Ahsay Go.

    Microsoft 365 Business Microsoft 365 Business Essentials
    Microsoft 365 Business Premium Microsoft 365 Enterprise E1
    Microsoft 365 Enterprise E3 Microsoft 365 Enterprise E3
    Microsoft 365 Enterprise E5 Microsoft 365 Education
  • Microsoft 365 Subscription Status

    Make sure your Microsoft 365 subscription with Microsoft is active in order to enjoy all privileges that come along with our backup services. If your account has expired, renew it with Microsoft as soon as possible so that you can continue enjoy the Microsoft 365 backup services provided by Ahsay Go.

    When your account is expired, depending on your role, certain access restrictions will be applied to your account. Refer to the URL below for more details.

    Microsoft 365 Subscription Status

  • Restore Requirement

    When restoring data of Microsoft 365 user, the account which the data will be restored to requires valid license(s):

    • Requires Exchange License

      Example: Exchange Online Plan and Microsoft 365 E3 are required when restoring Outlook's / Public Folder's items.

    • Requires SharePoint License

      Example: SharePoint Online Plan and Microsoft 365 E3 are required when restoring OneDrive's / Personal Site's items.


Microsoft 365 Permission Requirement

The basic permissions required by a Microsoft user account for authentication of a Microsoft 365 backup set is as follows:

  • Global Admin Role

    The Microsoft 365 account used for authentication must have Global Admin Role, since Modern Authentication will be used.

    This is to ensure that the authorization configuration requirements will be fulfilled (e.g. connect to Microsoft Azure AD to obtain the App Access Token). To assign the role, please refer to Assigning Global Admin Role to Accounts.

    Alternatively, if for some reason the Global Administrator Role cannot be granted, the following permissions must be granted instead:

    • Application Administrator
    • Exchange Administrator
    • SharePoint Administrator
    • Teams Administrator

    Please refer to Assigning Alternate Permissions to Accounts for instructions on how to assign the roles.

  • Term Store Administrator Role

    The Term Store Administrator Role may be required for backup and restore of SharePoint items. To assign the role, please refer to Granting Term Store Administrator Role.

  • A member of Discovery Management security group

    The Discovery Management security group must be assigned the following roles. To assign the role, please refer to Granting Permission Discovery Management Group.

    • Legal Hold
    • Mailbox Import Export
    • Mailbox Search
    • Public Folders

Otherwise, proceed to grant all necessary permissions to the Microsoft user account as shown in the following sections:


Assigning Global Administrator Role to Accounts

  1. Click the App launcher in the upper left side.

    app

  2. Click Admin to go to the Microsoft 365 admin center.

    admin

  3. In the "Microsoft 365 admin center", on the left panel click Active users under "Users". Find the user you want to assign the Global Admin role and click Manage roles.

    active1

    active2

  4. In the "Manage admin roles" window, select Admin center access then tick the box beside Global Administrator. Click Save changes to save the role you assigned.

    manage


Assigning Alternate Permissions to Accounts

  1. Click the App launcher in the upper left side.

    app

  2. Click Admin to go to the Microsoft 365 admin center.

    admin

  3. In the "Microsoft 365 admin center", on the left panel click Active users under "Users". Find the user you want to assign the role and click Manage roles.

    active1

    active2

  4. In the “Manage admin roles” window, select Admin center access then tick the box beside Application Administrator, Exchange Administrator, SharePoint Administrator, and Teams Administrator. Click Save changes to save the role you assigned.

    Manage Admin Roles


Granting Term Store Administrator Role

To add Term Store Administrator role to the Microsoft 365 user account used to authenticate the Microsoft 365 backup set.

  1. In the "SharePoint admin center", under "Content services", click Term store.

    term

  2. In the tree view pane in the middle, select Taxonomy. Then click Edit in the “Term store” section on the right.

    taxonomy

  3. The “Edit term store admins” panel appears. Enter the names or email addresses of the Microsoft 365 user who you want to add as term store admins then click Save.

    editterm


Granting Permission Discovery Management Group

This permission allows users added under the Assigned section of the “Discovery Management” group (refer to Granting Permission to Accounts for Creating Backup Set for setup) to back up and/or restore user item(s) not only for their account but also the accounts of other users in the same Assigned section.

  1. Open https://admin.exchange.microsoft.com/
  2. Log in to Microsoft 365 as an account administrator.

    login

  3. Select Admin roles which is under “Roles” on the left, then click Discovery Management in the middle. Click Permissions on the right.

    discovery

  4. Tick the box beside the roles you want to add. These are the following roles:

    • Legal Hold
    • Mailbox Import Export
    • Mailbox Search
    • Public Folders

    management

    You can find the roles above easily by making use of the Search section.

    discoverynote

  5. Click Save to confirm and click the X to exit the setting.

Granting Permission to Accounts for Creating Backup Set

  1. Open https://admin.exchange.microsoft.com/
  2. Log in to Microsoft 365 as an account administrator.

    login

  3. Select Admin roles which is under “Roles” on the left, then click Discovery Management in the middle. Click Assigned on the right, then click Add.

    assigned

  4. You can now add users to this group. Search by name or email address then click Add once done.

    discovmanage

    addadmin


Granting Permission to Restore All Share link types to Alternate location in Microsoft 365

To successfully restore all share link types to alternate location of the same organization in Microsoft 365, follow the settings below:

Allowing Anonymous Users to Access Application Pages:

  1. Click the App launcher in the upper left side.

    app

  2. Click SharePoint to go to the SharePoint page.

    sharepoint

  3. Click Settings>Site Settings

    sitesettings

  4. Under "Site Collection Administration", click Site collection features.

    sitecollection

  5. Scroll down and look for “Limited-Access user permission lockdown mode”, click the Deactivate button.

    deactivate

  6. Click Deactivate this feature.

    deacfeature

    Once deactivated, the Deactivate button will no longer be available.

    unavailable


Allowing Sharing to External Users:

  1. Go to your “Microsoft 365 admin center”, click All admin centers, then select SharePoint in the right pane.

    alladmin

  2. Go to Policies>Sharing. Under “External sharing” the button must be in line with “Existing guests” and click Save.

    policiessharing


Microsoft 365 API Permission Requirements

Microsoft will be retiring the Exchange Web Services (EWS) in Exchange Online starting October 1, 2026 and will be completely shutdown by April 1, 2027. Due to this development, backup and restore support for Outlook Archive, Teams Group Mail and Public Folders will be affected. Ahsay Go v10.3.2 will still continue to back up these items until Microsoft stops the EWS API service. After the said date, these three data types will no longer be supported.

Microsoft Graph will be used as a substitute for EWS, so additional API permissions are needed to be set up. For details on how to grant these API permissions, please refer to Microsoft Graph API Permissions.


Data Synchronization Check (DSC) Setup

To compensate for the significant backup performance increase, there is a tradeoff made by the Change Key API, which skips the checking of de-selected files in the backup source, which over time can result in a discrepancy between the items or files/folders selected in the backup sources and the those in the backup destination(s). However, the Change Key API will continue to check for de-selected Microsoft 365 user accounts or Site Collections. Un-selected individual Microsoft 365 user accounts or Site Collections detected during a backup job and will be automatically moved to retention area.

To overcome this, it is necessary in some cases to run a Data Synchronization Check (DSC) periodically. The DSC is similar to a regular Microsoft 365 Change Key API backup job but with the additional checking and handling of de-selected files and/or folders in the backup source. So that it will synchronize the data in the backup source and backup destination(s) to avoid data build-up and the freeing up of storage quota.

Here are the pros and cons of performing the DSC.

  Enabled Disabled
Backup time

Since DSC is enabled, it will only run on the set interval. For example, the default number of interval is 60 days.

The backup time for the data synchronization job which is triggered every 60 days by default will take longer than the usual backup as it is checking the de-selected files and/or folders in the backup source and data in backup destination(s).

As DSC is disabled, the backup time will not be affected.
Storage Management of storage quota will be more efficient as it will detect items that are de-selected and move it to retention and will be removed after it exceeds the retention policy freeing up the storage quota. Management of storage quota will be less efficient even though files and/or folders are already de-selected from the backup source, these files will remain in the data area of backup destination(s).

dsyncprocess

To setup the Data Synchronization Check (DSC), refer to the Set Up Data Synchronization Check (DSC).


Supported Services

Below are the supported services of Microsoft 365 Backup module. It is also specified in the table some services that are currently not supported by the Microsoft 365 Backup module.

suppservices


Below are the supported Outlook Mailbox types of Microsoft 365 Backup.

Mailbox


Below are the items that you can back up or restore from an Outlook mailbox.

Mailbox Items


Below are the items that you can back up or restore from OneDrive.

onedrive


Below are the items that you can backup or restore from Teams Chat / Channel.

teamsitems


Below are the Site Collections/Personal Site items that you can back up or restore from a Microsoft 365 backup set.

Site Collections


Below are the SharePoint Site Collections template that you can back up or restore from a Microsoft 365 backup set.

SharePoint Site Level Collection


Below is the Site Column Type that you can back up or restore from a Microsoft 365 backup set.

sitecolumn


Maximum Supported File Size

The following table shows the maximum supported file size per item for backup and restore of each service.

https://www.ahsay.com/sites/default/files/users_guide_page/4176/images/max-supported-filesize-m365-2x.webp

maxsuppsize